--- David Irvine <[EMAIL PROTECTED]> wrote:

---------------------------------
  Many thanks for a fantastic explanation and for
taking the time tohelp me. I was just reading some
docs there pointing me to this but youhave saved me a
good few hours. 

I will search out info for python info on PBKDF2 many
thanks for that.Just quickly though in point 3 does
that mean I should use ECB mode ornot if I am going to
split the file and send two parts to
differentlocations?

Girish:

You should avoid ECB mode at all costs. Always go for
CBC mode. ECB mode is just too easy to crack.

I will try to give you an intuitive explanation of the
difference bet CBC and ECB.

In ECB , each block of the file is encrypted
independently. So crackers can very easily correlate
cipher data and launch a chosen ciphertext attack or
some such.

But in CBC mode, this is made very difficult by virtue
of the fact that each successive plaintext block is
not only encrypted with the secret key schedule, but
also X-ORed with the ciphertext of the previous block.


This ensures that the "diffusion" part of block
ciphering is really thorough.

After all encryption is nothing but confusion and
diffusion...

Feel free to ask whatever basic questions you have.
:-)

Also don't get too hung up with IV. It is enough if
you are able to generate a secret key with good
entropy.

All the best!

regards,
Girish

__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [email protected]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to